What is Phishing? Attack Types and Prevention Guide

Phishing is a cyberattack in which someone sends a fraudulent message — usually email — that appears to come from a trusted source to trick the recipient into revealing sensitive information or running malicious code. The goal is almost always one of three things: steal login credentials, capture financial details, or get malware onto a device. Because so much phishing arrives by email and relies on forged sender identities, it is blunted directly by email authentication: SPF, DKIM, and DMARC.
How does phishing work?
Phishing attacks rely on deception and social engineering to push a victim into acting before they think. A typical campaign moves through five stages:
The typical flow of a phishing attack.
- Crafting the message. Attackers mimic a real organization using a spoofed
From:address, familiar logos, and urgent language ("Your account is locked"). Domains that have not published a DMARC policy are the easiest to impersonate. - Targeting victims. Messages go to harvested or purchased lists — either in bulk, or tailored to a specific person, which is known as spear phishing.
- Delivering the payload. The message pushes one action: clicking a link to a fake login page, opening an attachment that installs malware, or replying with sensitive details.
- Exploiting weaknesses. Phishing succeeds when authentication is missing or misconfigured, letting spoofed mail slip past filters, and when users aren't trained to spot the signs.
- Cashing in. Once the victim engages, the attacker harvests data for identity theft, fraud, or a wider network breach — often using the compromised account to phish others.
Common types of phishing
Phishing is an umbrella term. The variants worth knowing:
- Bulk phishing — generic messages blasted to huge lists, betting on volume.
- Spear phishing — a targeted message crafted for one person or team, using details that make it convincing.
- Whaling — spear phishing aimed at executives, often to authorize a wire transfer or share payroll data.
- Clone phishing — a legitimate email the victim already received, copied and re-sent with the links or attachments swapped for malicious ones.
- Smishing and vishing — the same tactics delivered by SMS or voice call instead of email.
Why phishing is a problem
Phishing is the entry point for a large share of serious breaches, and the damage compounds:
- Data breaches. Stolen credentials or malware expose personal and corporate data, leading to financial loss or identity theft.
- Financial fraud. Harvested details are used to drain accounts, make unauthorized purchases, or trigger fraudulent invoices.
- Network compromise. A single malicious attachment can plant ransomware or a backdoor for a much larger intrusion.
- Reputation damage. When attackers spoof your domain, your customers receive the scam — eroding trust in your brand, especially without DMARC or BIMI to prove which mail is genuinely yours.
How to defend against phishing
Stopping phishing takes both technical controls and trained people — neither is enough alone.
Combating phishing requires technical and human defenses.
- Authenticate your email. Publish SPF, DKIM, and a DMARC policy at enforcement (
p=quarantineorp=reject) so receivers reject mail that forges your domain. Add MTA-STS to force encrypted delivery between servers. - Filter aggressively. Modern mail gateways score sender reputation, link destinations, and content anomalies to quarantine suspicious messages before they reach an inbox.
- Train users. Teach people to distrust unexpected urgency, hover over links before clicking, and verify any request for money or credentials through a second channel.
- Harden configuration. Correct MX records, PTR records, and TLS reduce the routing weaknesses attackers abuse.
- Monitor continuously. Read your DMARC reports to spot who is trying to send as your domain, and tighten policy as you confirm your legitimate sources.
Related reading
Frequently asked questions
Keep going with AI
Ask AI how this applies to you
Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


